update master-with-bazel from master branch
This commit is contained in:
+1
-1
@@ -1,6 +1,6 @@
|
||||
module boringssl.googlesource.com/boringssl
|
||||
|
||||
go 1.19
|
||||
go 1.21
|
||||
|
||||
require (
|
||||
golang.org/x/crypto v0.17.0
|
||||
|
||||
@@ -2339,15 +2339,6 @@ func unexpectedMessageError(wanted, got any) error {
|
||||
return fmt.Errorf("tls: received unexpected handshake message of type %T when waiting for %T", got, wanted)
|
||||
}
|
||||
|
||||
func isSupportedSignatureAlgorithm(sigAlg signatureAlgorithm, sigAlgs []signatureAlgorithm) bool {
|
||||
for _, s := range sigAlgs {
|
||||
if s == sigAlg {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
var (
|
||||
// See RFC 8446, section 4.1.3.
|
||||
downgradeTLS13 = []byte{0x44, 0x4f, 0x57, 0x4e, 0x47, 0x52, 0x44, 0x01}
|
||||
|
||||
@@ -18,6 +18,7 @@ import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"math/big"
|
||||
"slices"
|
||||
)
|
||||
|
||||
type signer interface {
|
||||
@@ -35,7 +36,7 @@ func selectSignatureAlgorithm(version uint16, key crypto.PrivateKey, config *Con
|
||||
}
|
||||
|
||||
for _, sigAlg := range config.signSignatureAlgorithms() {
|
||||
if !isSupportedSignatureAlgorithm(sigAlg, peerSigAlgs) {
|
||||
if !slices.Contains(peerSigAlgs, sigAlg) {
|
||||
continue
|
||||
}
|
||||
|
||||
@@ -68,7 +69,7 @@ func signMessage(version uint16, key crypto.PrivateKey, config *Config, sigAlg s
|
||||
}
|
||||
|
||||
func verifyMessage(version uint16, key crypto.PublicKey, config *Config, sigAlg signatureAlgorithm, msg, sig []byte) error {
|
||||
if version >= VersionTLS12 && !isSupportedSignatureAlgorithm(sigAlg, config.verifySignatureAlgorithms()) {
|
||||
if version >= VersionTLS12 && !slices.Contains(config.verifySignatureAlgorithms(), sigAlg) {
|
||||
return errors.New("tls: unsupported signature algorithm")
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user